this sucks, but it works. centos should really just build the damn ca-certificates package for centos5 found on centos6
cp /etc/pki/tls/certs/ca-bundle.crt /root/ca-bundle.crt-old
curl http://curl.haxx.se/ca/cacert.pem -o /etc/pki/tls/certs/ca-bundle.crt